DNS Zone Transfer Enabled (AXFR)

Low Severity Technical Guide

Vulnerability Description

Allowing anonymous DNS zone transfers exposes the entire internal topology, subdomains, and server names of your infrastructure to potential attackers.

Remediation Guide

To resolve this vulnerability, follow these config changes or developer practices:

Disable zone transfers (AXFR) for anonymous clients on your DNS servers. Restrict transfers to specifically authorized secondary DNS server IP addresses.

Verify Your Fix

After applying the remediation, run an external attack-surface scan to verify that the vulnerability is no longer detected by WebScanify.

Is your website vulnerable?

Run a free security scan now to identify missing headers, outdated JS, and other deployment vulnerabilities.